Skip to content

fix: address Cursor plugin public-release blockers - #6

Merged
hassiebp merged 1 commit into
mainfrom
hassiebbot/cursor-public-release-blockers
Oct 1, 2026
Merged

hassiebp merged 1 commit into
mainfrom
hassiebbot/cursor-public-release-blockers

Conversation

@hassiebp

@hassiebp hassiebp commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Fixes the five P1 findings blocking the Cursor plugin's public launch:

  • Prevent project-only host overrides from receiving credentials inherited from the user configuration or environment. Projects with their own complete key pair remain supported; an explicit environment host still wins.
  • Apply file-read and tool-output capture settings before local persistence and again when exporting older events. Document the limits for prompts, edits, and shell/MCP content.
  • Mask configured Langfuse keys in observation names and attributes, including error status messages, and propagated identity/tag fields.
  • Add the Node shebang so the npm command and project hooks execute correctly on Unix.
  • Generate and ship licenses, notices, and source attribution for all 16 bundled dependencies.

Keeps the committed, self-contained dist/ installation and regenerates it. P2 findings from the review are outside this PR.

Validation: formatting and typecheck pass; all 79 tests pass, including localhost OTLP capture/redaction regressions and a packed-binary smoke test. A real npm installation into a temporary prefix executes successfully. Rebuilding produces no dist/ changes.

Fixes https://linear.app/clickhouse/issue/LFE-16866/fix-public-release-blockers-in-cursor-observability-plugin

@linear-code

linear-code Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
LFE-16866 Fix public-release blockers in Cursor observability plugin

Motivation

Prepare langfuse/cursor-observability-plugin for a public launch by fixing the five P1 findings from the pre-publication review.

Confirmed behavior

Using the shipped bundle and a localhost receiver with fake credentials: a project-only baseUrl override receives global credentials; captureFileContent=false still uploads Read tool results; captureToolOutput=false still persists raw results locally; configured keys leak through observation status messages; the npm binary has no Node shebang and fails when executed on Unix. The committed bundle also redistributes OpenTelemetry and Langfuse dependencies without their license/notice texts.

Scope and intended changes

  1. Prevent project host overrides from redirecting inherited credentials while preserving explicit user/environment routing and self-contained project credentials.
  2. Apply capture policy before event persistence and again at export, covering file-read and generic/shell/MCP output paths. Document limits for prompts, generated edits, and shell commands that read files.
  3. Redact configured Langfuse keys throughout emitted observation attributes, including status messages.
  4. Add the executable shebang and validate the packed package's command.
  5. Generate and ship third-party licenses/notices for the actual bundled dependency graph.

Keep the committed self-contained dist bundle: Cursor's Git installation requires it. Update documentation and regenerate dist.

Validation and rollout

Add focused regression tests and local OTLP receiver checks; run formatting, typecheck, build, full tests, reproducible-bundle checks, and packed-package smoke tests. Publish one draft PR; do not merge, release a package, or change repository visibility.

Non-goals

The review's P2 findings (retry/persistence, duplicate stops, attached-trace IDs, concurrency, setup safety and file permissions) remain separate follow-ups.

Review in Linear

@hassiebp
hassiebp marked this pull request as ready for review October 1, 2026 08:23

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c01fb88284

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

for (const chunk of Object.values(bundle)) {
if (chunk.type !== "chunk") continue;
for (const id of Object.keys(chunk.modules)) {
if (!id.includes(`${path.sep}node_modules${path.sep}`) || !fs.existsSync(id)) continue;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Accept normalized module IDs on Windows

When pnpm build or prepack runs on Windows, Rolldown supplies normalized module IDs with / separators, while path.sep is \. This check therefore skips every bundled dependency, leaves entries empty, and later fails the build with No bundled dependency licenses found. Match both separator styles (or normalize id) so Windows contributors can rebuild and package the plugin.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T08:25:37.092337Z c01fb88 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@hassiebp
hassiebp merged commit 6cd18a7 into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant